By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: NetaceaPublished February 9, 2026

TL;DR: Automated risk will shift in 2026 from simple bot blocking to behavioural governance, as declared LLM scraping and agentic browsing increasingly drive economic extraction, pricing distortion, and delegated automation risk, according to Netacea. The critical change is that identity alone cannot control systems that adapt in real time; intent and behaviour must become the primary control signals.


At a glance

What this is: This is a forecast for 2026 automated threat trends, arguing that AI agents, LLM crawlers, and delegated automation will outpace identity-based controls and demand behaviour-led governance.

Why it matters: It matters to IAM and security teams because machine access is increasingly acting like a governed identity problem, while static allowlists, declared identity, and binary bot controls fail to constrain agentic behaviour.

By the numbers:

👉 Read Netacea's forecast for AI-driven threats in 2026


Context

Automated access is becoming a governance problem because systems can now act at business speed while presenting as legitimate traffic. For AI agents, LLM crawlers, and delegated automation, the central failure is not simple authentication, but the gap between declared identity and observable behaviour across content, pricing, and transactional systems.

Netacea’s forecast reflects a broader identity security pattern: once machine actors can browse, optimise, and repeat actions at scale, traditional bot controls and static access rules lose precision. That creates a direct intersection with NHI governance, because the practical question becomes how to classify, constrain, and audit automated actors that behave like identities but do not fit human IAM assumptions.


Key questions

Q: How should security teams govern AI agents that browse and transact on behalf of users?

A: Security teams should govern AI agents as delegated actors with narrow, task-scoped permissions, not as enhanced browsers. The right model is to bind access to the specific action being performed, preserve auditability at the transaction layer, and separate machine identity from the human principal wherever possible.

Q: Why do declared identities fail to control automated traffic effectively?

A: Declared identities fail because they describe what automation claims to be, not what it does after access is granted. In practice, a trusted label can cover behaviour that extracts data, distorts pricing, or concentrates requests on sensitive assets. Effective control depends on runtime observation, not static reputation or self-declaration.

Q: What breaks when allow and block rules are used for agentic traffic?

A: Binary allow and block rules break because agentic traffic changes behaviour dynamically. A rule that allows legitimate automation can also permit harmful optimisation at scale, while a block rule can disrupt useful indexing or partner workflows. The missing capability is conditional governance, where policy can constrain, verify, or revoke based on how the traffic behaves.

Q: Who is accountable when automated access causes pricing or margin distortion?

A: Accountability usually sits with the team that authorised the automation and the team that owns the business process it touched. Security, product, and platform owners all need shared governance because the harm often happens inside permitted access. Frameworks that support this include zero trust policy design, IAM governance, and formal review of delegated automation.


Technical breakdown

Declared identity versus behavioural intent

Declared identity tells you what an automated actor claims to be, not what it is trying to accomplish. In AI-driven traffic, user-agent strings, published purposes, and partner labels are weak signals because the same automation can shift from benign indexing to content extraction or commercial arbitrage without changing its declared form. Behavioural intent analysis looks at sequence, depth, revisit rate, and target sensitivity to infer purpose from actions. That is why this problem sits at the boundary of bot management, IAM, and NHI governance: the control target is no longer a username, but a runtime pattern of access.

Practical implication: govern automated access by observed behaviour and sensitivity thresholds, not by declared labels alone.

Why agentic browsing breaks static allow and block models

Agentic browsing is different from classic scraping because an agent can receive a goal, explore options, and adapt its path in real time. That makes traditional binary controls too coarse. Allow rules permit too much once a trusted pattern is established, while block rules suppress legitimate automation that business teams actually need. The result is control collapse at scale, especially where pricing, inventory, editorial content, or other revenue-linked systems are exposed. This is where bot defence becomes a governance function, with policy deciding when traffic may continue, when it must step up, and when it must be constrained.

Practical implication: define step-up verification and scope limits for agentic traffic before optimisation loops start distorting business outcomes.

Bot and agent trust management as an identity-adjacent control model

Bot and agent trust management is the idea that automated actors should be evaluated continuously for confidence, scope, and economic intent. It is not just another security filter. It combines behavioural telemetry, policy enforcement, and conditional access decisions so that automation remains accountable as it moves across websites, applications, and APIs. For identity teams, the important insight is that this resembles lifecycle governance for non-human actors: access is granted, constrained, reviewed, and revoked based on current behaviour rather than static registration alone.

Practical implication: build governance for automated actors that includes review, revocation, and policy change based on runtime risk.


Threat narrative

Attacker objective: The objective is to extract economic value at scale by using trusted automation to influence or consume business systems faster than human-paced controls can respond.

  1. Entry begins when AI crawlers or delegated agents obtain legitimate access through declared identities, trusted automation frameworks, or user-authorised browsing flows.
  2. Escalation occurs when the same access is used to broaden navigation, increase request volume, or concentrate on commercially sensitive pages and workflows.
  3. Impact follows as the automation extracts value, distorts pricing logic, erodes margins, or exposes operational data without triggering conventional breach alerts.

NHI Mgmt Group analysis

Declared identity is no longer a reliable control boundary for automated actors. Once a crawler, agent, or delegated workflow can imitate legitimate access, who it says it is becomes a weak governance signal. Behaviour, scope, and intent are the controls that matter, especially when the same actor can move from harmless automation to commercial extraction in one session. Security programmes should treat declared identity as context, not authorisation.

Agentic traffic creates a new governance gap: access can be legitimate while the outcome is still harmful. That distinction matters because many control models are built to stop unauthorised entry, not to manage authorised behaviour that depletes margin, distorts pricing, or extracts content. This is a named concept worth tracking as behaviour-led economic abuse, where the risk sits inside permitted access rather than at the perimeter. Practitioners need governance models that assess what automation is doing, not just whether it was allowed in.

Bot and Agent Trust Management is becoming the practical analogue of lifecycle governance for non-human actors. The market is moving toward continuous assessment, step-up enforcement, and revocation based on runtime signals because static registration does not capture operational drift. That aligns more closely with NHI governance than with traditional bot blocking, because the object being controlled is an identity-like software actor with changing risk over time. Teams should expect this category to pull bot defence, IAM, and fraud controls closer together.

Identity security teams should read this as a signal that machine identity controls must expand beyond secrets and service accounts. AI crawlers and agents may not be classic NHIs, but they still create governance questions about attribution, scope, auditability, and accountability. That convergence means IAM and NHI programmes will increasingly need shared policy language for delegated automation, especially where access is business-authorised but economically sensitive. The practical conclusion is that identity boundaries must now extend into runtime behaviour.

The market is signalling a shift from prevention-only controls toward conditional participation models for automation. That does not mean opening the door wider. It means defining when automation is allowed, when it must be constrained, and when it should be denied because the business case no longer holds. For identity and security leaders, this validates a broader move toward contextual governance across human and non-human access alike.

What this signals

Behavioural governance will become the practical control layer for agentic traffic. The important shift for programmes is not whether automation is allowed, but whether its activity can be measured, constrained, and explained in business terms. Teams that already track runtime access patterns can extend those controls to AI agents and delegated workflows without rebuilding their entire governance model.

Machine identity and NHI programmes will need shared language for delegated access. AI agents blur the line between application automation and identity governance because they can act with authorisation while still creating risk. That convergence means identity teams should start aligning policy, audit, and lifecycle review with the same standards used for other non-human actors, including 52 NHI Breaches Analysis where lifecycle failure is the recurring issue.


For practitioners

  • Define behavioural policy for automated access Classify automated actors by observed behaviour, not just by declared crawler or agent labels. Set thresholds for depth, frequency, revisit patterns, and access to commercially sensitive assets, then map those thresholds to step-up controls or denial.
  • Separate legitimate automation from economic extraction Create policy paths for indexing, partner automation, and agentic browsing so that beneficial traffic is not blocked by default. Use commercial intent, content sensitivity, and usage drift as decision inputs rather than a single allowlist.
  • Add auditability for delegated and synthetic identities Require logs that show which pages, data classes, or workflows an agent touched, how its access changed over time, and who authorised the delegation. This is essential for compliance review, dispute resolution, and incident investigation.
  • Use step-up verification when optimisation crosses boundaries Trigger stronger checks when agents expand across pricing, inventory, editorial, or operational data, or when volume and revisit rates rise sharply. The objective is to preserve business intent without breaking all automation.

Key takeaways

  • AI-driven automation is turning identity from a static access problem into a behavioural governance problem.
  • The evidence from current deployments shows that agents already exceed intended scope often enough to justify immediate control redesign.
  • Security leaders need conditional, runtime policy for automated actors before economic distortion becomes a normal operating condition.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10The article centers on agentic browsing, tool use, and delegated automation risk.
MITRE ATT&CKTA0007 , Discovery; TA0010 , ExfiltrationThe threat model includes exploratory access and value extraction through automated actors.
NIST CSF 2.0PR.AC-4Behaviour-based access governance aligns with access control and least-privilege outcomes.
NIST SP 800-53 Rev 5IA-5The article's access problem includes credential and authenticator governance for automation.
NIST Zero Trust (SP 800-207)Continuous verification fits the article's call for runtime governance of automation.

Use ATT&CK to map automated discovery and extraction behaviours to runtime detections and containment rules.


Key terms

  • Declared Identity: The identity an automated system claims when it requests access, such as a crawler label, partner tag, or agent descriptor. Declared identity helps with attribution, but it is not a reliable control on its own because behaviour can diverge from the stated purpose after access is granted.
  • Behavioural Intent: The purpose inferred from what an automated actor actually does once it is inside a system. Security teams derive behavioural intent from access sequence, navigation depth, revisit patterns, and target sensitivity, then use that signal to decide whether the automation should continue, step up, or stop.
  • Bot and Agent Trust Management: Bot and agent trust management is the practice of classifying non-human and AI-assisted traffic so security systems can decide whether to allow, challenge, or block it. It combines identity signals, device evidence, and behavioural analysis to determine intent rather than assuming all automation is hostile.
  • Agentic Traffic: Traffic generated by software that can act on behalf of a user or process with some degree of independent decision-making. In fraud prevention, it includes both legitimate assistants and malicious automation, so the control question becomes intent and behaviour, not automation alone.

What's in the full article

Netacea's full blog covers the operational detail this post intentionally leaves for the source:

  • How the vendor distinguishes declared identity from behavioural intent in automated traffic
  • Operational examples of step-up verification and denial logic for revenue-critical systems
  • Practical policy patterns for governing LLM crawlers, partner automation, and agentic browsing
  • The vendor's framing of bot and agent trust management for large-scale automation

👉 The full Netacea blog covers behaviour-led control models, economic extraction patterns, and agentic browsing risk in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and workload identity. It is built for practitioners who need to translate identity policy into operational control across human and non-human access.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org